The Senior SOC Analyst is responsible for advanced security monitoring, incident investigation, threat hunting, detection engineering, incident response, and security automation. The role requires strong hands-on experience in investigating complex cybersecurity incidents, identifying attacker behaviors and TTPs, developing and tuning security detections, and designing automated SOC workflows using SOAR platforms. The analyst is expected to continuously improve SOC detection and response capabilities by identifying detection gaps, reducing false positives, improving investigation processes, and automating repetitive security operations. Key Responsibilities
Perform advanced investigation and analysis, containment, eradication, recovery, root cause analysis, and post-incident review.
Conduct proactive threat hunting using SIEM, EDR/XDR, network, authentication, and application telemetry.
Map security incidents and detection scenarios to the MITRE ATT&CK framework.
Develop, implement, test, and tune SIEM correlation and detection rules.
Reduce false positives and continuously improve detection accuracy and coverage.
Develop and maintain SOC playbooks, runbooks, investigation procedures, and incident response procedures.
Support digital forensic and malware analysis activities when required.
Coordinate with infrastructure, network, endpoint, application, DevOps, and security engineering teams during security incidents.
Analyze incident trends and contribute to SOC metrics, reports, lessons learned, and continuous improvement initiatives.
Design, develop, implement, and maintain SOAR workflows and automated incident response playbooks.
Technical Skills
Strong hands-on experience with SIEM and detection engineering, preferably Splunk Enterprise Security, including SPL, correlation rules, data models, and Risk-Based Alerting (RBA).
Experience with SOAR and security automation, including playbook development, REST APIs, JSON, webhooks, and security-system integrations.
Strong knowledge of incident response, threat hunting, advanced log analysis, event correlation, and MITRE ATT&CK/TTP analysis.
Strong understanding of Windows, Linux, Active Directory, identity security, and network protocols, including TCP/IP, DNS, HTTP/HTTPS, TLS, VPN, firewalls, and proxies.
Knowledge of web application attacks and OWASP techniques, as well as malware behavior, persistence, privilege escalation, credential access, lateral movement, defense evasion, and command-and-control techniques.
Experience with digital forensics, malware analysis, IOC investigation, and Threat Intelligence platforms such as MISP.
Experience with network security analysis tools such as Zeek, Suricata, Snort, and Wireshark.
Experience & Qualifications
5+ years of cybersecurity experience, with strong hands-on experience in SOC operations, incident response, threat hunting, detection engineering, or security automation.
Practical experience developing and tuning SIEM detection and correlation rules.
Practical experience designing or implementing SOAR workflows and security automation.
Strong understanding of enterprise network, endpoint, identity, application, and security architectures.
Ability to independently investigate incidents from initial detection through containment, root cause analysis, and lessons learned.
Ability to translate attacker behaviors and investigation findings into new detections, hunting scenarios, and automation workflows.
Strong technical documentation, analytical, problem-solving, and communication skills.
Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or a related field is preferred; equivalent practical experience is also acceptable.
Job Requirements
Gender
Men / Women
Education
Bachelor| Computer and IT
Software
Wireshark| Intermediate Active Directory| Intermediate Linux| Intermediate
ثبت مشکل و تخلف آگهی
ارسال رزومه برای توسعه فناوری گروه فارابی
برای دیدن سوابق ارسال رزومه، لطفا وارد حساب کاربری خود شوید.